Malicious PDF — malware analysis report

Static analysis result for SHA-256 e98c24b963cae030…

MALICIOUS

PDF

155.5 KB Created: 2021-02-25 07:41:23 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-22
MD5: 871dcf4be5b9f3b00f0baeb5a9fb225e SHA-1: 773f2549f471e63acfb07d574b7c0b24d235dbcb SHA-256: e98c24b963cae0307cdb5113568c407d2c9a3c7d826ba36b95e9c8d37e7196c7
126 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains numerous external links, many hosted on disposable domains, and is flagged by ML classifiers and ClamAV as malicious. The presence of embedded URLs and the PDF structure suggest an attempt to redirect the user to malicious content, likely for phishing or to download further payloads. The document body contains obfuscated text and references to URLs, indicating a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9437

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://maypoin.ru/123?utm_term=scout+motto+do+your+best PDF link annotation
    • https://letotanuvimipe.weebly.com/uploads/1/3/4/5/134598603/ca4b4a950d.pdfIn PDF document text
    • https://buzubexod.weebly.com/uploads/1/3/4/0/134017192/3206043.pdfIn PDF document text
    • http://frontglass.xyz/mudam6w98r.pdfIn PDF document text
    • https://litazivufili.weebly.com/uploads/1/3/4/3/134305244/gupafesegobumuv.pdfIn PDF document text
    • http://blue-tick-central.com/exercicios_resolvidos_trigonometria_no_triangulo_retangulo_9_anolyqmv.pdfIn PDF document text
    • https://penotogales.weebly.com/uploads/1/3/1/4/131438478/milifaferi-jonitugevo-nodajabena.pdfIn PDF document text
    • https://zemilogafolot.weebly.com/uploads/1/3/4/0/134096074/6e42b75457cecdd.pdfIn PDF document text
    • http://lazerepil.site/kemakbzf3z.pdfIn PDF document text
    • http://mitutepoka.medianewsonline.com/bajebatizalonebok.pdfIn PDF document text
    • https://wegabikiwapalev.weebly.com/uploads/1/3/5/9/135992979/tekugiw.pdfIn PDF document text
    • http://nuloriwilorij.scienceontheweb.net/vishnu_sahasranama_stotram_in_english.pdfIn PDF document text
    • http://xufededubumavif.scienceontheweb.net/pumakivunifomozotadusibe.pdfIn PDF document text
    • http://vilopeg.xyz/suwematobuwaguxetix7b18k.pdfIn PDF document text
    • https://cdn.sqhk.co/sopiloroda/QwicKLE/vibumi.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://fedorahosted.org/lohitIn PDF document text
    • http://www.thdl.org/http://www.thdl.org/TibetanIn PDF document text
    • http://www.opentle.orgIn PDF document text
    • https://s3.amazonaws.com/sikuva/swarm_simulator_beginner_guide.pdfIn PDF document text
    • https://s3.amazonaws.com/sezewu/vakifinijipe.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlTibetanIn PDF document text
    • http://www.gnu.org/licenses/lgpl.htmlRegularDanhHongIn PDF document text
    • http://www.geocities.com/dnhhngIn PDF document text
    • http://sinhala.sourceforge.net/In PDF document text
    • http://sinhala.cvs.sourceforge.net/viewvc/*checkout*/sinhala/sinhala/fonts/CREDITSIn PDF document text
    • http://www.gnu.org/licenses/gpl-2.0.htmlIn PDF document text
    • http://www.gnu.org/licenses/gpl.htmlIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • http://scripts.sil.orgIn PDF document text

Extracted artifacts 14

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00011462.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11462 7712 bytes
SHA-256: d8f1955146d32d9908bf049c7016689a10cd875baf1d55d5699d5ec293a685a7
font_01_sfnt_off00012803.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12803 5708 bytes
SHA-256: dc63d0570acafeafc55ca0423c3fb3128bb84d5496a42695849c7f41cbdb439d
font_02_sfnt_off00013be3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13BE3 5188 bytes
SHA-256: 8c7ff81ca007ffb5e96183d858d256a86c87c5509d5a8f6eb61bd66aa7c55026
font_03_sfnt_off00014d73.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x14D73 4424 bytes
SHA-256: e3ebc139050552a3e3e4c2e9be5e851d294fa8462befbbb7d11f2a2a41619ac4
font_04_sfnt_off00015d55.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x15D55 6660 bytes
SHA-256: 5e7e543e3212bce12b0c413a08b9806b45db6444217b771eee1cbcdb8072e344
font_05_sfnt_off00017301.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x17301 10048 bytes
SHA-256: f69884180aec74c402629d5832980184f1de3191e9b116d7ed80e20dd3a3a06d
font_06_sfnt_off000187e2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x187E2 5428 bytes
SHA-256: c2c377376bbae5726fe7486e8df9e786e2e666977dc19ff454fc5fab8552e2d1
font_07_sfnt_off00019849.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x19849 6580 bytes
SHA-256: bd3e5c3097fc689426a6c4d05c6a80c6f5cf330deed1342440c18863b64c4e5d
font_08_sfnt_off0001ad6d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1AD6D 7348 bytes
SHA-256: 3b29cda0a52d240538d5f770d2d26e43bdc212992bebfc75f71340db9ee4d588
font_09_sfnt_off0001c1ab.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1C1AB 22556 bytes
SHA-256: a369ca6be5840495dd88e3fb24b105563fbff8c09a72e642258afa64066ab312
font_10_sfnt_off000200af.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x200AF 23476 bytes
SHA-256: b77f7ae1a743007d83426ea9f53e4a3a2b2d4e5567b19edfbba0ab2f5067a6ec
font_11_sfnt_off00022e65.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x22E65 3124 bytes
SHA-256: fcba279cc1dd6d09688fcd308e24579769bca9fe494bc2cb02734fad4b452bfe
font_12_sfnt_off00023b01.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x23B01 4524 bytes
SHA-256: 4c5c8894fb3d431d82354a4e6fecf09f290e5d862fd2792f51bcac7487c5ab4f
font_13_sfnt_off00024981.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x24981 6844 bytes
SHA-256: 7227844a4fd64fa184984f7094fc3b08cd152e0fcdde74a9e6e525fbf5a31644